blog-scraper

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: RSS scraping behavior is aligned with the stated purpose and uses a standard PyPI dependency, but the optional fallback relies on an unpinned third-party Apify Store actor outside the publisher's control. The requested Apify token is proportionate, yet forwarding it into community-hosted actor execution raises medium supply-chain and credential-forwarding risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 24, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fblog-scraper%2F@82970d9eabddd4e64a9ce548a9b0de10395252e3